CISM Audible Exam Quiz Phil Martin Flashcards

1
Q

standard

A

tells how to carry out a policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

procedure

A

clear list of steps required to accomplish a task

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

procedure defines 4 things

A

required conditions

information displayed

expected outcome

what to do when unexpected happens

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

biased assimilation

A

when we accept only facts that support our perspective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

risk appetite

A

amount of risk a business is willing to incur

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

risk tolerance

A

amount of deviation from the risk appetite that a business considers acceptable

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

risk capacity

A

amount of risk a business can absorb without dying

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

3 phases of octave

A

locate all assets, build threat profile
locate all network paths and it components
assign risk to each asset and decide what to do with it

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

operationally critical threat asset and vulnerability evaluation (OCTAVE)

A

risk approach for when you need well established process to id, prioritize and manage risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Bowtie analysis

A

risk approach that creates a visual diagram with the event in the middle (knot)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly